Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I wonder what the best convention for generating secure brainwallets is. They seem much more prone to dictionary attacks if you're not careful. Is inventing words and nonsensical phrases the norm?


Using a brain wallet in any form is reckless. You're better off storing your private key on paper or using SSSS[0].

[0]: http://point-at-infinity.org/ssss/


Well, for one thing, don't use just one round of SHA-256. Or more generally: don't use the same algorithm as everyone else. Chain together different hash functions, and/or run them more than once.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: